2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34287 | HIGH | 7.8 | 0.3% | Oct 30, 2025 | Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodical... |
| CVE-2025-34286 | HIGH | 7.2 | 2.2% | Oct 30, 2025 | Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run C... |
| CVE-2025-34284 | HIGH | 8.8 | 4.2% | Oct 30, 2025 | Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validatio... |
| CVE-2025-34283 | MEDIUM | 6.5 | 0.9% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Nept... |
| CVE-2025-34280 | HIGH | 7.2 | 1.3% | Oct 30, 2025 | Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management function... |
| CVE-2025-34278 | MEDIUM | 5.4 | 0.7% | Oct 30, 2025 | Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source... |
| CVE-2025-34277 | CRITICAL | 9.8 | 2.0% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID value... |
| CVE-2025-34274 | CRITICAL | 9.8 | 1.9% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs... |
| CVE-2025-34273 | MEDIUM | 6.5 | 0.9% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administ... |
| CVE-2025-34272 | MEDIUM | 6.5 | 0.8% | Oct 30, 2025 | In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the applicatio... |
| CVE-2025-34271 | CRITICAL | 9.8 | 0.7% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting ... |
| CVE-2025-34270 | MEDIUM | 4.9 | 0.6% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fa... |
| CVE-2025-34269 | — | — | — | Oct 30, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2... |
| CVE-2025-34249 | — | — | — | Oct 30, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2... |
| CVE-2025-34135 | MEDIUM | 4.4 | 0.3% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. ... |
| CVE-2025-34134 | HIGH | 7.2 | 2.2% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligenc... |
| CVE-2025-8850 | HIGH | 8.8 | 0.4% | Oct 30, 2025 | In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow.... |
| CVE-2025-63423 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator passw... |
| CVE-2025-61498 | HIGH | 7.5 | 0.4% | Oct 30, 2025 | A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (... |
| CVE-2025-61141 | HIGH | 7.5 | 1.1% | Oct 30, 2025 | sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes ... |
| CVE-2025-3356 | CRITICAL | 9.8 | 0.4% | Oct 30, 2025 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t... |
| CVE-2025-3355 | HIGH | 7.5 | 0.5% | Oct 30, 2025 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t... |
| CVE-2025-63422 | HIGH | 7.5 | 0.3% | Oct 30, 2025 | Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRou... |
| CVE-2025-63298 | HIGH | 8.2 | 0.5% | Oct 30, 2025 | A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/... |
| CVE-2025-62265 | MEDIUM | 5.4 | 0.2% | Oct 30, 2025 | Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now